Denial-of-Service Vulnerability in libsoup HTTP Library by GNOME
CVE-2025-4948

7.5HIGH

What is CVE-2025-4948?

A vulnerability exists in the libsoup HTTP library's soup_multipart_new_from_message() function, utilized by GNOME and other applications for handling web communications. This flaw arises from improper validation when processing specially crafted multipart messages. The resulting integer underflow can lead to invalid memory access, causing affected applications or servers to crash unexpectedly. Thus, any application relying on libsoup is at risk of experiencing a denial-of-service, which may disrupt service availability and user access.

Affected Version(s)

Red Hat Enterprise Linux 10 0:3.6.5-3.el10_0.6

Red Hat Enterprise Linux 8 0:2.62.3-9.el8_10

Red Hat Enterprise Linux 8 0:2.62.3-9.el8_10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank fouzhe and zkbytes for reporting this issue.
.
CVE-2025-4948 : Denial-of-Service Vulnerability in libsoup HTTP Library by GNOME